splunk / contentctl

Splunk Content Control Tool
Apache License 2.0
82 stars 21 forks source link

Improve filter macro checking #165

Closed pyth0n1c closed 2 months ago

pyth0n1c commented 3 months ago

Improve checking to ensure that a filter macro is included in each detection and that the filter macro has the proper name (which is deterministically calculated from the name of the detection/filename itself).

pyth0n1c commented 2 months ago

Tests all look good, including against security_content!